MGASA-2013-0232
Dashboard / Vulnerabilities / MGASA-2013-0232
Summary: Updated file-roller package fixes CVE-2013-4668
Details: Updated file-roller package fixes security vulnerability: Directory traversal vulnerability in File Roller 3.6.x before 3.6.4 when libarchive is used, allows remote attackers to create arbitrary files via a crafted archive that is not properly handled in a "Keep directory structure" action, related to fr-archive-libarchive.c and fr-window.c (CVE-2013-4668).
References: https://advisories.mageia.org/MGASA-2013-0232.html, https://lists.fedoraproject.org/pipermail/package-announce/2013-July/111666.html, https://bugs.mageia.org/show_bug.cgi?id=10782
Affected packages
Package
Name: file-roller
Purl: pkg:rpm/mageia/file-roller?arch=source&distro=mageia-3
Affected ranges
Type: ECOSYSTEM
Events:
